Hush Line Fixes Security Issue in Whistleblower Management System
CVE-2024-55888
7.1HIGH
Key Information:
- Vendor
- Scidsg
- Status
- Hushline
- Vendor
- CVE Published:
- 12 December 2024
Summary
Hush Line, an open-source whistleblower management system, has a vulnerability due to a misconfigured production server that fails to implement a content security policy or necessary security headers. This flaw, present in versions 0.1.0 to 0.3.4, potentially enables attackers to bypass cross-site scripting (XSS) filters, which could compromise the security of user data and the application. The vulnerability has been addressed in version 0.3.5, which includes critical security updates.
Affected Version(s)
hushline >= 0.1.0, < 0.3.5
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved